litellm/litellm-rust/crates/secrets-google/tests/kms.rs
devin-ai-integration[bot] 19556952d9
feat(secrets): route secret resolution through native Rust backends (#42619)
* fix(secrets): verify provider API request and payload contracts

* wip

* fix(secrets): unify backend reads and route secret resolution

* feat(secrets): bind built-in managers to retained Rust backends

* refactor(secrets): centralize catalog dispatch and native binding

* test(secrets): split provider integration tests

* refactor(secrets): enforce cache and rotation contracts

* test(secrets): stub parent packages in failing resolver fixture

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* refactor(secrets): pass manager settings through the interop boundary

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(secrets): align cloud KMS auth and harden provider reads

* ci(rust): raise native wheel size gate to 40 MB for secrets backends

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(proxy): treat unset google kms flag as disabled like the old loader

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(secrets): preserve certificate credentials and disabled KMS flags

* test(secrets): cover certificate validation and bounded auth retries

* test(secrets): cover Python dispatch without the native extension

* test(proxy): skip legacy secret manager cases when the optional SDK is missing

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(secrets): port Python parity tests and preserve provider behavior

* fix(secrets): store the captured native config without setattr to satisfy the strict lint budget

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(secrets): preserve missing Azure manager values

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* test(secrets): pin typed values and recovery failure precedence

* refactor(secrets): organize provider internals and behavioral test suites

* refactor(secrets): simplify recovery and isolate Python compatibility

* fix(secrets): distinguish Azure callback absence from HTTP not found

* fix(secrets): preserve Python AWS read results at the bridge

* fix(secrets): route public reads through the native catalog bridge

* fix(secrets): keep JSON selection outside the bridge

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(secrets): preserve provider JSON reads at the bridge

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(secrets): preserve Python primary JSON semantics

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* fix(secrets): preserve CyberArk mutation behavior through the native bridge

* docs(secrets): record public API replacement gaps

* refactor(secrets): share Vault write payload preparation

* feat(secrets): route Vault mutations through the native bridge

* fix(secrets): preserve typed Vault rotation failures

* refactor(secrets): move Python dispatch into bridge

* refactor(secrets): move CyberArk Python policy into bridge

* refactor(secrets): move Vault Python policy into bridge

* test(secrets): assert Vault rotation request paths

* fix(secrets): keep bridge JSON interop centralized

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

---------

Co-authored-by: Yujong Lee <yujong@berri.ai>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-23 08:24:57 -07:00

109 lines
3.4 KiB
Rust

use base64::{Engine, engine::general_purpose::STANDARD};
use google_cloud_kms_v1::client::KeyManagementService;
use litellm_core_utils::settings::Lookup;
use litellm_secrets_google::{Error, GoogleKms, kms::validate_environment};
use rstest::rstest;
use wiremock::{
Mock, MockServer, ResponseTemplate,
matchers::{body_json, path},
};
#[rstest]
#[tokio::test]
async fn google_kms_decrypts_using_the_configured_resource() {
let server = MockServer::start().await;
let resource = "projects/project/locations/global/keyRings/ring/cryptoKeys/key";
Mock::given(path(format!("/v1/{resource}:decrypt")))
.and(body_json(
serde_json::json!({"ciphertext":STANDARD.encode("encrypted")}),
))
.respond_with(
ResponseTemplate::new(200)
.set_body_json(serde_json::json!({"plaintext":STANDARD.encode(" value\n")})),
)
.expect(1)
.mount(&server)
.await;
let client = KeyManagementService::builder()
.with_endpoint(server.uri())
.with_credentials(google_cloud_auth::credentials::anonymous::Builder::new().build())
.with_retry_policy(google_cloud_gax::retry_policy::NeverRetry)
.build()
.await
.unwrap();
let manager = GoogleKms::new(client, resource.into());
assert_eq!(
manager.decrypt(b"encrypted".to_vec()).await.unwrap(),
b" value\n"
);
}
#[rstest]
#[case::unset(None)]
#[case::disabled(Some(false))]
#[tokio::test]
async fn disabled_google_kms_loader_does_not_read_environment_configuration(
#[case] enabled: Option<bool>,
) {
use std::sync::Arc;
assert!(
litellm_secrets_google::load_google_kms(
enabled,
Arc::new(|name: &str| panic!("disabled Google KMS read {name}")),
)
.await
.unwrap()
.is_none()
);
}
#[rstest]
#[tokio::test]
async fn enabled_google_kms_loader_accepts_application_default_credentials() {
use std::sync::Arc;
let environment = Arc::new(|name: &str| {
(name == "GOOGLE_KMS_RESOURCE_NAME")
.then(|| "projects/project/locations/global/keyRings/ring/cryptoKeys/key".to_owned())
});
assert!(
litellm_secrets_google::load_google_kms(Some(true), environment)
.await
.unwrap()
.is_some()
);
}
#[rstest]
#[case::resource_missing(None, None, "GOOGLE_KMS_RESOURCE_NAME")]
fn enabled_google_kms_requires_resource_name(
#[case] credentials: Option<&str>,
#[case] resource: Option<&str>,
#[case] missing: &'static str,
) {
let environment = move |name: &str| match name {
"GOOGLE_APPLICATION_CREDENTIALS" => credentials.map(str::to_owned),
"GOOGLE_KMS_RESOURCE_NAME" => resource.map(str::to_owned),
_ => None,
};
assert!(matches!(
validate_environment(&environment as &dyn Lookup),
Err(Error::MissingEnvironment(name)) if name == missing
));
}
#[rstest]
#[case::service_account_file(Some("credentials"))]
#[case::application_default_credentials(None)]
fn google_kms_environment_is_valid_without_required_credential_file(
#[case] credentials: Option<&str>,
) {
let environment = |name: &str| match name {
"GOOGLE_APPLICATION_CREDENTIALS" => credentials.map(str::to_owned),
"GOOGLE_KMS_RESOURCE_NAME" => Some("resource".to_owned()),
_ => None,
};
assert!(validate_environment(&environment as &dyn Lookup).is_ok());
}